Back to skill

Security audit

Meverylucky AI Agent

Security checks for vulnerabilities and agentic risk

Overview

This identity skill is mostly coherent, but it handles long-lived private keys with unsafe defaults that users should review before installing.

Review this before installing if the agent identity will matter outside a test environment. Set BILLIONS_NETWORK_MASTER_KMS_KEY before creating identities, avoid passing private keys on the command line, restrict access to $HOME/.openclaw/billions, rotate any keys previously stored in plaintext, and treat signed tokens/challenges as sensitive because challenge replay protection is weak.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/shared/storage/keys.js:44
Finding

Private keys are stored in plaintext by default without enforced restrictive file permissions

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/verifySignature.js:19
Finding

Authentication challenges can be replayed because they neither expire nor get consumed

Content
View full analysis
entry.did === did); if (index >= 0) { // Update existing entry entries[index] = { did, challenge, created_at }; } else { // Add new entry entries.push({ did, challenge, created_at }); } await this.writeFile(entries); } async find(did) { const entries = await this.readFile(); return entries.find((entry) => entry.did === did); } async getChallenge(did) { const entry = await this.find(did); return entry?.challenge; } ``` `scripts/verifySignature.js:19-60`: ```js const { kms, challengeStorage } = await getInitializedRuntime(); // Get the stored challenge const challenge = await challengeStorage.getChallenge(args.did); if (!challenge) { console.error(`Error: No challenge found for DID: ${args.did}`); console.error("Generate a challenge first with generateChallenge.js"); process.exit(1); } // Create DID resolver that fetches from remote resolver const resolveDIDDocument = { resolve: async (did) => { const resp = await fetch( `https://resolver.privado.id/1.0/identifiers/${did}`, ); const didResolutionRes = await resp.json(); return didResolutionRes; }, }; // Create JWS packer and unpack token const jws = new JWSPacker(kms, resolveDIDDocument); const basicMessage = await jws.unpack(byteEncoder.encode(args.token)); // Verify the sender if (basicMessage.from !== args.did) { console.error( `Error: Invalid from: expected from ...[truncated 2757 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (37)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 97)May include surrounding context.

md
| `identities.json`  | Identity metadata                                                                  |
| `defaultDid.json`  | Active DID and associated public key                                               |
| `challenges.json`  | Per-DID challenge history                                                          |
| `credentials.json` | Verifiable credentials                                                             |

There are several ways of storing private keys, to enable master key encryption as described in the **KMS Encryption** section below.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The declared description suggests a full decentralized identity integration centered on Billions, ERC-8004, attestation registries, and iden3-based authentication proof workflows. The actual code chunk only retrieves and displays existing identities from storage. That is identity-related, but it does not implement the key described capabilities or primary purpose. This is a material description-behavior mismatch rather than a mere supporting utility detail, because the code's concrete function is a simple identity listing script rather than proof generation/verification or agent-human identity linking.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description presents a blockchain/decentralized identity skill centered on agent-human identity linking, attestation registries, and authentication proof workflows. The supplied code chunk only provides generic local file storage for identity objects. It does not interact with blockchain registries, ERC-8004, iden3 protocols, authentication proofs, or any network/external identity systems. While file storage could be a supporting implementation detail within a larger identity system, this chunk by itself does not accurately represent the declared purpose and instead has a much narrower, materially different behavior.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_prompt_injection_hidden_instructions': Prompt injection or hidden instructions embedded in AI agent skill text [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 10)May include surrounding context.

entity description: Billions decentralized identity for agents. Link agents to human identities using Billions ERC-8004 and Attestation Registries. Verify and generate authentication proofs. Based on iden3 self-sovereign identity protocol. metadata: { "category": "identity", "clawdbot": { "requires": { "bins": ["node"] } } } homepage: https://billions.network/

When to use this Skill

Lets AI agents create and manage their own identities on the Billions Network, and link those identities to a human owner.

  1. When you need to link your agent identity to an owner.
  2. When you need to sign a challenge.
  3. When you need to link a human to the agent's DID.
  4. When you need to verify a signature to confirm identity ownership.
  5. When you use shared JWT tokens for authentication.
  6. When you need to create and manage decentralized identities.

After installing the plugin run the following commands to create an identity and link it to your human DID:

bash
cd scripts && npm inst

Credential Access

High
Category
Privilege Escalation
Confidence
86% confidence
Finding

The skill documents the location and contents of highly sensitive files, including kms.json containing private keys and credentials.json containing verifiable credentials, and notes that keys may be stored in plaintext when an environment variable is not set. In an agent setting, a skill centered on identity management and local credential storage is inherently high risk because any overbroad file access, logging, or prompt-driven exfiltration could expose long-lived secrets and identity artifacts.

Content

Scanner excerpt · SKILL.md (reported line 172)May include surrounding context.

md
- `kms.json` - **CRITICAL**: Contains private keys (encrypted if BILLIONS_NETWORK_MASTER_KMS_KEY is set, otherwise in plaintext)
- `defaultDid.json` - DID identifiers and public keys
- `challenges.json` - Authentication challenges history
- `credentials.json` - Verifiable credentials
- `identities.json` - Identity metadata
- `profiles.json` - Profile data

Known Vulnerable Dependency: ws==8.18.0 — 2 advisory(ies): CVE-2026-45736 (ws: Uninitialized memory disclosure); CVE-2026-48779 (ws: Memory exhaustion DoS from tiny fragments and data chunks)

High
Category
Supply Chain
Confidence
95% confidence
Finding

ws 8.18.0 is present and carries advisories for memory disclosure and memory-exhaustion denial of service. In an agent identity skill that may maintain network/WebSocket connections to blockchain or verifier services, a vulnerable WebSocket stack meaningfully increases exposure to remote attacks and service instability.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: brace-expansion==2.0.2 — 4 advisory(ies): CVE-2026-13149 (brace-expansion: DoS via exponential-time expansion of consecutive non-expanding); CVE-2026-33750 (brace-expansion: Zero-step sequence causes process hang and memory exhaustion); CVE-2026-14257 (brace-expansion: DoS via unbounded expansion length causing an out-of-memory pro) +1 more

High
Category
Supply Chain
Confidence
84% confidence
Finding

brace-expansion 2.0.2 is present and has multiple denial-of-service advisories related to pathological expansion behavior. This is a real vulnerable package in the dependency tree, but in this context it is likely only reachable through tooling or ancillary parsing paths rather than core runtime identity verification logic.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: fast-uri==3.1.0 — 7 advisory(ies): CVE-2026-13676 (fast-uri vulnerable to host confusion via failed IDN canonicalization); CVE-2026-18446 (fast-uri vulnerable to host confusion via backslash authority introducer); CVE-2026-75975 (fast-uri vulnerable to server-side request forgery via malformed IPv6 normalizat) +4 more

High
Category
Supply Chain
Confidence
93% confidence
Finding

fast-uri 3.1.0 is present with multiple host confusion and SSRF-related advisories. In an identity skill that may fetch DIDs, JSON-LD contexts, attestation registries, or verifier endpoints, malformed URL parsing can materially increase risk by misrouting requests or enabling SSRF against internal services.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: ws==7.5.10 — 1 advisory(ies): CVE-2026-48779 (ws: Memory exhaustion DoS from tiny fragments and data chunks)

High
Category
Supply Chain
Confidence
94% confidence
Finding

ws 7.5.10 is flagged for memory exhaustion DoS and is present in the dependency graph. If reachable through RPC/WebSocket features used by blockchain integrations, a remote peer could degrade or crash the process through crafted fragmented traffic.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: underscore==1.13.6 — 1 advisory(ies): CVE-2026-27601 (Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS)

High
Category
Supply Chain
Confidence
86% confidence
Finding

underscore 1.13.6 is flagged for unlimited recursion in _.flatten and _.isEqual, enabling potential DoS on crafted nested data. In an identity/proof-processing ecosystem that may compare or flatten attacker-supplied JSON-like objects, this can become practically relevant even if the vulnerable functions are only used transitively.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: undici==5.29.0 — 12 advisory(ies): CVE-2026-1525 (Undici has an HTTP Request/Response Smuggling issue); CVE-2026-6733 (undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse); CVE-2026-1527 (Undici has CRLF Injection in undici via `upgrade` option) +9 more

High
Category
Supply Chain
Confidence
96% confidence
Finding

undici 5.29.0 is present with numerous advisories including request smuggling, queue poisoning, and header injection classes of issues. This is especially concerning for an identity-verification skill that likely performs outbound HTTP to registries, issuers, DID resolvers, or JSON-LD resources, because network-layer confusion could undermine integrity, confidentiality, or availability.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: ws==8.17.1 — 2 advisory(ies): CVE-2026-45736 (ws: Uninitialized memory disclosure); CVE-2026-48779 (ws: Memory exhaustion DoS from tiny fragments and data chunks)

High
Category
Supply Chain
Confidence
95% confidence
Finding

ws 8.17.1 is present and affected by memory disclosure and memory exhaustion advisories. Given the presence of blockchain and RPC-related libraries, this WebSocket issue is credibly reachable in real deployments and could expose process memory or cause denial of service from remote peers.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

The bootstrap code stores credential data in a local file named credentials.json alongside identity-related artifacts, and the same module also initializes file-backed key storage. In an agent identity context, these files may contain highly sensitive credentials or metadata; if stored unencrypted or with broad filesystem permissions, local compromise, backup leakage, or multi-user host access could expose identities and enable impersonation or correlation.

Content

Scanner excerpt · scripts/shared/bootstrap.js (reported line 54)May include surrounding context.

js
function newDataStorage(ethStateStorage) {
  return {
    credential: new CredentialStorage(
      new IdentitiesFileStorage("credentials.json"),
    ),
    identity: new IdentityStorage(
      new IdentitiesFileStorage("identities.json"),

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

When no master key is present, _encodeEntry stores privateKeyHex directly on disk under provider: "plain", meaning highly sensitive secret material is persisted unencrypted. In an agent identity system, compromise of the host, backups, logs, or filesystem access can immediately yield signing keys and allow impersonation, fraudulent attestations, or long-term identity takeover.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The README instructs users to run npx clawhub@latest install verified-agent-identity, which pulls and executes the latest package version at install time rather than a fixed, reviewed version. This creates a supply-chain risk: if the upstream package is compromised or a breaking/malicious release is published, users may execute attacker-controlled code during installation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The suggested phrase Please link your agent identity to me. is a natural-language trigger that could overlap with ordinary conversation and cause the skill to initiate a sensitive identity-linking workflow unintentionally. In an agent environment, ambiguous triggers are risky because another user, prompt injection, or surrounding context could activate identity operations without the operator clearly intending that exact action.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The human installation step again uses npx clawhub@latest, causing execution of whatever code is current in the registry at the time of install. Because npx executes fetched packages, this is a real supply-chain exposure rather than a documentation-only concern.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill advertises and instructs use of Node-based scripts that access local sensitive files under $HOME and interact with external identity/network systems, yet it declares no explicit tool scope or permission boundaries. In an agent environment, missing scope makes it easier for the skill to be invoked with broader-than-necessary filesystem, environment, or network access, increasing the blast radius of misuse or compromise.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill explicitly instructs users to supply a raw private key via a command-line flag. Command-line arguments are commonly exposed through shell history, process listings, logs, telemetry, and agent traces, which can leak the key and fully compromise the associated identity.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This code accepts a user-supplied private key or generates a new one, then derives a signer from it, but there is no confirmation prompt, user-facing warning, or explanatory message about handling sensitive credential material. Because private keys are highly sensitive, users should be clearly informed when the skill consumes or generates them.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The code initializes file-backed storage for KMS keys and later stores credentials, identities, DIDs, and challenges in JSON files. While comments describe the components, there is no confirmation prompt, user-facing log, or explicit warning that sensitive wallet material and identity data will be persisted locally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

This file configures external endpoints for the Billions Network RPC and a revocation service, and uses them to create state and credential status resolvers. Although the code comments describe the configuration, there is no visible user-facing notice that runtime data may be transmitted to external services.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The list() method returns every stored private key in raw form, greatly expanding exposure beyond what a normal key-management interface should provide. Any caller with access to this method can enumerate and exfiltrate all key material at once, which is especially risky in an identity/authentication skill where private keys represent agent identity and signing authority.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The verification flow hard-codes user-facing prompts such as "Please provide your DID to start verification" and "Please sign this challenge" without offering any language or locale choice. This can violate language/locale policy when a skill forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The script creates a wallet connected to a JSON-RPC provider using the configured mainnet URL, which causes interaction with an external network service. There is no visible user-facing notice in this file that blockchain RPC communication will occur or that related metadata may be transmitted.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.